Chapter 2: Hardware installation
| 41
BIH11-IHP User’s Manual
Restore Factory Keys
Force System to User Mode. Configure NVRAM to contain OEM-defined factory default Secure
Boot keys.
Restore To Setup Mode
Delete NVRAM content of all UEFI Secure Boot key databases.
Key Management
Factory Key Provision
This item Provision factory default keys on next re-boot only when System in Setup Mode.
Options: Disabled (Default) / Enabled
Restore Factory keys
This item Force System to User Mode. Configure NVRAM to contain OEM-defined factory
default Secure Boot keys.
Restore To Setup Mode
This item Delete NVRAM content of all UEFI Secure Boot key databases.
Export Secure Boot variables
It allows you to copy NVRAM content of Secure Boot variables to files in a root folder on a file
system device.
Enroll Efi Image
It allow the image to run in Secure Boot mode. Enroll SHA256 Hash certificate of a PE image
into Authorized Signature Database (db).
Remove ‘UEFI CA’ from DB
This item device Guard ready system must not list ‘Microsoft UEFI CA’ Certificate in Authorized
Signature database (db).
Restore DB defaults
This item restore DB variable to factory defaults.
Platform Key (PK)
Options: Details / Export / Update / Delete
Key Exchanges Keys
Options: Details / Export / Update / Append / Delete
Authorized Signatures
Options: Details / Export / Update / Append / Delete